5.1
CVSSv2

CVE-2006-4827

Published: 15/09/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and previous versions allow remote malicious users to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.

Vulnerable Product Search on Vulmon Subscribe to Product

vmist downstat 1.2

vmist downstat 1.3

vmist downstat 1.4

vmist downstat 1.5

vmist downstat

vmist downstat 1.6

vmist downstat 1.7

Exploits

DESCRIPTION: Remote file include vuln found by sZ [sept, 8 2006] SOFTWARE: downstat 18 VENDOR URL: vmistnet/indexphp?script=Downstat DORKs: "Login To Downstat 18" allinurl:"/downstat/" NOTES: greetz to: neo-vortex, sk0tie, icez visit @ ircbluehellorg #silenz VULN CODE: ------ adminphp: if(!@include($art"in_phpphp")) exit(" ...